Cyber Threat Detection (Alert Development), Principal Associate
Capital OneAbout the role
Capital One’s Cyber Organization is a fast-paced, dynamic environment committed to enabling and securing the business. Our Cyber Operations & Intelligence division is searching for an experienced Individual Contributor (IC), Principal Associate to contribute to our Detection Engineering team. In this role, you will be responsible for solving hard problems using cutting edge technology in the areas of security testing, engineering, alert development, and monitoring.
Responsibilities:
Develop, deploy, and maintain using Detection-as-Code methodology and MITRE ATT&CK framework to measure coverage
Develop signature and behavioral based detections
Work with partners and stakeholders to onboard additional detection capabilities and tooling
Ability to conduct proactive threat research across enterprise environments using hypothesis driven methodologies
Develop and implement best practices to identify malicious activity in a dynamic, fast-paced environment
Understand the business drivers of the enterprise and partner with relevant stakeholders to ensure robust monitoring and expanded coverage across our hosts, networks, and applications.
Demonstrate a deep understanding of adversary techniques and emerging threats that could impact business operations
Respond to inquiries from regulatory entities, risk management and audit teams, providing clear and complete documentation of procedures and workflows
Experience mentoring junior engineers and contribute to a culture of continuous improvement and knowledge sharing
Ability to articulate security risks and detection strategies to technical and executive audiences
About you:
Previous experience with a detection engineering, threat detection, or detection operations team
Extensive experience in SQL
Strong understanding of attacker TTPs, red team methodologies, and translating offensive security insights into detections
Excellent analytical, communication, and leadership skills
Must be able to perform root cause analysis independently or collaboratively with team
Customer service and stakeholder engagement skills
Strong decision-making and strategic thinking in threat detection
Basic Qualifications:
High School Diploma, GED, or equivalent certification
At least 3 years of experience in Information Technology or Cyber Security
At least 2 years of experience with host, cloud, application or network logs
At least 2 years of experience developing alerts for threat detection
Preferred Qualifications:
Bachelor’s Degree in Information Technology, Cyber Security or Computer Science or similar programs
4+ years of experience in Threat Detection, Threat Hunting, or Security Engineering
4+ years of experience with data science
4+ years of experience with Python
2+ years of pentesting or offensive security experience
1+ years of experience in publishing code to Github
GCIA, GCIH, CISSP, GMON, GREM, GCTD, MLE, or Cloud (GCP, AWS) certifications
At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, or another type of work authorization).
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $158,600 - $181,000 for Prin Assoc, Cyber Technical
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s